mirror of
https://github.com/supabase/supabase.git
synced 2026-10-10 20:05:06 +03:00
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? ~~This is the first part (and ultimately the final part of the stacked PR). PR 1 introduces mock data for us while we build the requirements of the scoped oauth interstitial, all following PR's will be stacked on top of this one.~~ This is the first part, the data layer side. We began with mock data, but as backend support arrived we've used this PR to help us shape the UI as well as the frontend data layer. This now acts as the frontend data layer. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added OAuth app authorization request handling. * Added visibility into application details, requested scopes, and existing authorizations. * Added organization and project selection during authorization. * Added organization roles and project access details. * Added approval and denial options with secure redirect handling. * Added validation for required authorization details and project selections. * Added support for role validation feedback during approval. * Added representative authorization scenarios for approved, denied, and re-consent flows. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> Co-authored-by: Gildas Garcia <1122076+djhi@users.noreply.github.com> Co-authored-by: Samir Ketema <6003000+samirketema@users.noreply.github.com>
105 lines
5.1 KiB
JSON
105 lines
5.1 KiB
JSON
{
|
|
"$schema": "https://unpkg.com/knip@6/schema-jsonc.json",
|
|
// Only files + dependencies are gated in CI for now; the export/type surface
|
|
// has too much noise to enforce yet.
|
|
"exclude": ["types", "exports"],
|
|
"ignore": [
|
|
"examples/**",
|
|
"**/*.mdx",
|
|
// skip supabase functions
|
|
"supabase/functions/**",
|
|
"**/*.test.ts",
|
|
// ignore registry blocks in ui-library
|
|
"apps/ui-library/registry/default/**",
|
|
"apps/ui-library/contentlayer.config.js",
|
|
],
|
|
"workspaces": {
|
|
"apps/studio": {
|
|
// Framework-convention files: nothing in source imports these, the
|
|
// framework/host discovers them by path. They are `entry` rather than
|
|
// `ignore` so knip still traces what they import — an ignored file's
|
|
// imports are invisible, which makes everything only it pulls in look
|
|
// dead.
|
|
"entry": [
|
|
// TanStack Start. knip's tanstack-router plugin only looks under
|
|
// `src/`, but vite.config.ts sets `srcDirectory: './'`, so the
|
|
// conventional files sit at the workspace root and have to be listed.
|
|
// routeTree.gen.ts is deliberately absent: router.tsx imports it, so
|
|
// it is traced already.
|
|
"router.tsx",
|
|
"start.ts",
|
|
// Route modules are real entry points. Keeping them as entries (not
|
|
// ignores) means components reachable only from the TanStack tree stay
|
|
// traced as the Next `pages/**` tree is dismantled.
|
|
"routes/**/*.{ts,tsx}",
|
|
// Next.js compat shims. Reached only through the `nextShims` aliases in
|
|
// vite.config.ts (`next/link` -> compat/next/link.tsx), which knip
|
|
// cannot resolve, so they need to be entries in their own right.
|
|
"compat/**/*.{ts,tsx}",
|
|
],
|
|
"ignore": [
|
|
"public/**",
|
|
// one-off build/codegen scripts, run by hand or from package.json
|
|
"scripts/**",
|
|
// dynamically imported
|
|
"components/interfaces/ConnectSheet/content/**",
|
|
"components/interfaces/ConnectSheet/DirectConnectionExamples.tsx",
|
|
// data layer templates, copied when adding a new query/mutation
|
|
"data/__templates/**",
|
|
// evals are run from a GitHub action, not from the app
|
|
"evals/**",
|
|
],
|
|
// Narrowly scoped suppressions: one issue type, one path. Preferred over
|
|
// `ignore` (which drops the file from the project entirely, hiding the
|
|
// imports and dependencies it legitimately uses) and over
|
|
// `ignoreMembers` (which matches member names across the whole
|
|
// workspace).
|
|
"ignoreIssues": {
|
|
// graphql-codegen `client` preset output (scripts/codegen.ts,
|
|
// regenerated by `pnpm build:graphql-types`). The preset always emits
|
|
// the full set, so some of it is unreferenced by design. execute.ts in
|
|
// the same directory is hand-written and is NOT listed here.
|
|
"data/graphql/{fragment-masking,gql,graphql}.ts": ["files"],
|
|
// CONSTRAINT_TYPE mirrors the complete closed set of Postgres
|
|
// `pg_constraint.contype` values (c/f/p/u/t/x). The members we don't
|
|
// read are documentation of the valid values, not dead code. Scoped to
|
|
// this file so `enumMembers` keeps working everywhere else.
|
|
"data/database/constraints-query.ts": ["enumMembers"],
|
|
// Data contracts and mock hooks for the OAuth authorization
|
|
// interstitial, landed ahead of the UI that consumes them. `exports`
|
|
// and `types` cover the contract types that only gain consumers in the
|
|
// consent-screen PR.
|
|
// TODO(PROD-625): drop every oauth-apps knip exception in the
|
|
// consent-screen PR, once the interstitial route imports them.
|
|
"data/oauth-apps/**": ["files", "exports", "types"],
|
|
"hooks/misc/useTrackExperimentExposure.ts": ["files"],
|
|
// Staging-only pinned Postgres image + FDW request payload for creating
|
|
// Warehouse test projects by hand. Nothing imports it yet — it's kept
|
|
// alongside the rest of the Warehouse work so the values stay in one
|
|
// place until the project-creation surface that consumes them lands.
|
|
"components/interfaces/ProjectCreation/WarehouseFdwCustomImage.constants.ts": ["files"],
|
|
},
|
|
// `vercel` is a globally installed CLI used by the `deploy:staging` script
|
|
"ignoreBinaries": ["vercel"],
|
|
// Dependencies that are required implicitly — nothing imports them by a
|
|
// specifier knip can follow, but removing them breaks the build or the
|
|
// runtime.
|
|
"ignoreDependencies": [
|
|
// vite.config.ts resolves 'lodash-es/package.json' by string via
|
|
// createRequire to build the SSR lodash -> lodash-es alias
|
|
"lodash-es",
|
|
// named as a webpack/turbopack loader string in next.config.ts
|
|
// (`loaders: ['raw-loader']`)
|
|
"raw-loader",
|
|
// runtime hooks for @sentry/nextjs / OpenTelemetry Node
|
|
// instrumentation. Must be direct deps under pnpm's strict isolation
|
|
// (#35030).
|
|
"import-in-the-middle",
|
|
"require-in-the-middle",
|
|
// deliberate dependency-resolution pin (#45876), never imported
|
|
"@babel/core",
|
|
],
|
|
},
|
|
},
|
|
}
|